CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

    • Abyssian@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 hours ago

      Right. Why would you do this? Monitoring being available on the Intranet, of course. But controllers on the open internet?

      Might as well really focus on ease of use and just make a live website with one big button that says “cut off all electricity and turn all the water into poison, lol”

    • Duamerthrax@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      4 hours ago

      Remote monitoring? Sure. Remote managing? Fuck that. These facilities shouldn’t be unstaffed for days at a time.

      • Doomsider@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 hours ago

        Oh for sure, air gapped sensors that relay information are going to be necessary. We should be building these systems with absolute security because they are critical to infrastructure.

        • Duamerthrax@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 hours ago

          Some people will say it’s too hard to retrofit onto legacy equipment, but all it really means is adding a secondary system on top of the legacy system. Just a sensor array that has no interaction with existing systems.

          • SanicHegehog@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            22 minutes ago

            Yup. Fancy architecture diagram:

                              One Way Radio
                               Transmitter
            [Nuclear Reactor] ------------> [Internet connected receiver] -> tHe ClOUd
            
      • BrianTheeBiscuiteer@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 hours ago

        It’s called paying people to watch the systems during off-hours. It’s often way cheaper than setting up firewalls, setting up alerts, maintaining patches, paying a VPN company to manage connections, paying another company to handle authentication, and so on. Security constraints are getting so bad at my office I’m seriously thinking of how we can do more things with pen and paper.

    • HugeNerd@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 hours ago

      A simple 300 bps connection over POTS to relay the information from the process controller is all you need. But even POTS is disappearing.

    • nycvin@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 hours ago

      Exactly! Whenever I see one of these stories of a utility being hacked that’s my first thought.